CRITICALNuGet

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

CVE-2026-70354Published 2 weeks agoUpdated 1 week agoSource: OSV

Affected packages

  • Microsoft.WindowsDesktop.App.Runtime.win-arm6410.0.0 → 10.0.11
  • Microsoft.WindowsDesktop.App.Runtime.win-x6410.0.0 → 10.0.11
  • Microsoft.WindowsDesktop.App.Runtime.win-x8610.0.0 → 10.0.11

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability | HackTribune